This forum is in READ-ONLY mode.
You can look around, but if you want to ask a new question, please use the new forum.
Home » support » General discussion » Symfony Security issue - XSS attack on form helpers
icon4.gif  Symfony Security issue - XSS attack on form helpers [message #3872] Mon, 13 March 2006 23:19 Go to previous message
pookey  is currently offline pookey
Messages: 173
Registered: January 2006
Location: Epsom, Surrey, UK
Senior Member

Synopsis
--------

Symfony's input_tag form helper is vulnerable to cross site scripting attacks.

Affected Versions
-----------------

0.6, latest beta.
Possibly older versions too.

Description
-----------

The input_tag will display a value received in the request without sanitising it's content. More information on XSS can be found here - http://en.wikipedia.org/wiki/Cross_site_scripting.
A ticket for this bug has been opened on trac.

Impact
------

By exploiting the cross-site scripting vulnerabilities, an attacker can execute arbitrary scripts running in the context of the victim's browser. The severity of this issue will vary on a site to site basis.

Workaround
----------

Currently there is work arround.

Example
-------

http://www.askeet.com/search?search=test%22%3E%3Cscript%3Eal ert('XSS');%3C%2Fscript%3E%3Ci

[Updated on: Mon, 13 March 2006 23:43]


http://shurl.net - the only URL shortening service written with symfony!

Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Previous Topic:JSON - multiple ajax calls - revisited
Next Topic:[resolved] Using .htaccess password with myUser class
Goto Forum:

  

powered by FUDforum - copyright ©2001-2004 FUD Forum Bulletin Board Software